Role: Information Security Analyst (GRC)
Location: Phoenix, AZ (Local Candidates Only – Must reside within approximately 1 hour driving distance of Phoenix)
Work Arrangement: Hybrid/Remote within Arizona (in accordance with State of Arizona Remote Work Program guidelines)
Duration: 4-Month Contract-to-Hire
Conversion Requirement: Candidates must be eligible to convert to a full-time employee. Visa sponsorship is not available.
Important Notes
- Candidates must currently reside in Arizona and be within a reasonable commuting distance of Phoenix.
- Candidates must be eligible for permanent employment conversion after the contract period.
Position Overview
The client is seeking an experienced Information Security Analyst (ISA) to join the Governance, Risk, and Compliance (GRC) team.
This role will partner with business units and technology teams to support governance, risk management, compliance initiatives, security assessments, audits, and information security programs.
The selected candidate will play a key role in analyzing security requirements, identifying risks, developing compliance documentation, supporting audits, and ensuring adherence to regulatory and security frameworks.
The ideal candidate will possess strong cybersecurity governance experience, risk management expertise, audit knowledge, and the ability to communicate effectively with technical and non-technical stakeholders.
Key Responsibilities
- Perform information security risk assessments and compliance reviews.
- Conduct security audits and generate findings reports with actionable recommendations.
- Track remediation activities and Plan of Action & Milestones (POA&M) items.
- Develop detailed reports outlining findings, risks, non-compliance issues, incident observations, and corrective actions.
- Review, update, and maintain security plans, audit plans, risk documentation, and related governance artifacts.
- Evaluate security controls and ensure compliance with applicable regulatory and organizational requirements.
- Investigate suspicious activities and assist with incident reporting processes.
- Prepare audit documentation and supporting evidence for compliance reviews.
- Draft, edit, and finalize audit findings in accordance with agency standards and documentation requirements.
- Collaborate with business units to gather requirements and identify data dependencies.
- Develop logical and physical data models, system activity diagrams, and process documentation.
- Support technical project managers in requirements gathering and information analysis activities.
- Develop and maintain project artifacts, documentation, training materials, and user adoption resources.
- Provide guidance to stakeholders regarding information security best practices and compliance requirements.
- Research emerging cybersecurity regulations, standards, and industry best practices.
- Recommend process improvements to strengthen security posture and compliance maturity.
Required Qualifications
- Bachelor''s degree in Information Security, Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent professional experience.
- Experience performing security risk assessments, compliance reviews, and audit activities.
- Strong knowledge of Governance, Risk, and Compliance (GRC) principles.
- Experience developing and maintaining security policies, standards, and procedures.
- Experience creating audit reports, findings documentation, and remediation plans.
- Knowledge of Information Security Risk Management methodologies.
- Experience supporting compliance initiatives and security governance programs.
- Strong analytical, documentation, and communication skills.
- Ability to work independently and collaboratively across multiple business units and technical teams.
Required Security & Compliance Knowledge
Candidates should have working knowledge of:
- NIST 800-53 Revision 5
- IRS Publication 1075
- HIPAA / HITRUST
- CJIS
- MARS-E
- Risk Management Framework (RMF)
- Security Control Selection, Implementation, Assessment, and Auditing
- Information System Authorization Processes
- Internal Controls and Risk Management Practices
Technical Knowledge
Experience with one or more of the following:
- Windows Administration
- Unix/Linux Administration
- Database Technologies
- Software Development Environments
- Network Infrastructure and Security
- Security Monitoring and Incident Investigation
- Enterprise Information Security Programs
Preferred Qualifications
- Professional security certifications such as CISSP, CISM, CISA, CRISC, or similar.
- Public sector or government security compliance experience.
- Experience supporting enterprise-wide cybersecurity governance initiatives.
- Familiarity with security and privacy frameworks in highly regulated environments.
Required Skills & Competencies
- Strong written and verbal communication skills.
- Ability to create executive-level and technical documentation.
- Excellent analytical and problem-solving abilities.
- Strong stakeholder management and relationship-building skills.
- Ability to assess and improve security policies and procedures.
- Ability to identify risks and recommend practical mitigation strategies.
- Ability to interpret regulations, standards, and compliance requirements.
- Ability to work effectively in cross-functional teams.
- Strong organizational skills and attention to detail.
- Ability to manage multiple priorities in a fast-paced environment.
What Success Looks Like
- Security assessments and audits are completed accurately and on schedule.
- Compliance gaps are identified and documented effectively.
- Risk remediation efforts are tracked and communicated clearly.
- Security policies and governance processes remain current and compliant.
- Business stakeholders receive actionable guidance that improves security posture and compliance outcomes.